CISSP Security Assessment and Testing Practice Question
A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:
⚠ Common exam trap
CISSP often tests the distinction between KPI (process performance), KGI (goal achievement), and KRI (risk exposure) — candidates frequently confuse KPI with KRI because both involve metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Key Performance Indicator (KPI)
Mean time to remediate (MTTR) for critical vulnerabilities measures how efficiently the security team is performing remediation, making it a Key Performance Indicator (KPI). KPIs track the performance of processes and activities against operational targets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security baseline
Why it's wrong here
A security baseline defines the minimum set of security controls, configurations, and practices that must be implemented across systems or organizations to achieve a desired security posture. While essential for establishing a secure foundation, a baseline itself is a static standard or configuration, not a dynamic metric that measures the performance or efficiency of a security process over time, such as remediation speed. Therefore, it does not directly track operational performance.
- ✗
Key Goal Indicator (KGI)
Why it's wrong here
A Key Goal Indicator (KGI) is a high-level, strategic metric used to determine whether an organization has achieved its overarching business or security objectives. KGIs typically measure outcomes, such as "reduced overall cyber risk by 15%" or "achieved 99.9% system availability," rather than the efficiency of an internal process. Mean time to remediate is an operational metric reflecting process performance, not a direct measure of strategic goal attainment.
- ✓
Key Performance Indicator (KPI)
Why this is correct
A Key Performance Indicator (KPI) is a quantifiable metric used to evaluate the success of a particular activity, process, or project against predefined objectives. Mean time to remediate (MTTR) is an excellent example of a KPI because it directly measures the efficiency and effectiveness of the incident response and vulnerability management processes. Tracking MTTR allows security managers to assess operational performance, identify bottlenecks, and drive continuous improvement in their remediation efforts.
- ✗
Key Risk Indicator (KRI)
Why it's wrong here
A Key Risk Indicator (KRI) is a metric used to provide an early warning signal of increasing risk exposure, helping organizations anticipate and mitigate potential threats before they materialize into incidents. KRIs often track factors like the number of unpatched critical vulnerabilities or employee security awareness scores, which indicate potential future risk. While remediation impacts risk, "mean time to remediate" specifically measures the performance of the remediation process, rather than directly indicating an escalating risk level itself.
Go deeper
Related to this question
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.